Serectrix snc, Pescara, Italy.
Eur J Public Health. 2013 Apr;23(2):247-53. doi: 10.1093/eurpub/cks043. Epub 2012 May 4.
The EUBIROD project aims to perform a cross-border flow of diabetes information across 19 European countries using the BIRO information system, which embeds privacy principles and data protection mechanisms in its architecture (privacy by design). A specific task of EUBIROD was to investigate the variability in the implementation of the EU Data Protection Directive (DPD) across participating centres.
Compliance with privacy requirements was assessed by means of a specific questionnaire administered to all participating diabetes registers. Items included relevant issues e.g. patient consent, accountability of data custodian, communication (openness) and complaint procedures (challenging compliance), authority to disclose, accuracy, access and use of personal information, and anonymization. The identification of an ad hoc scoring system and statistical software allowed an overall quali-quantitative analysis and independent evaluation of questionnaire responses, automated through a dedicated IT platform ('privacy performance assessment').
A total of 18 diabetes registers from different countries completed the survey. Over 50% of the registers recorded a maximum score for accountability, openness, anonymization and challenging compliance. Low average values were found for disclosure and disposition, access, consent, use of personal information and accuracy. A high heterogeneity was found for anonymization, consent, accuracy and access.
The novel method of privacy performance assessment realized in EUBIROD may improve the respect of privacy in each data source, reduce overall variability in the implementation of privacy principles and favour a sound and legitimate cross-border exchange of high quality data across Europe.
EUBIROD 项目旨在使用 BIRO 信息系统在 19 个欧洲国家之间跨境流动糖尿病信息,该系统在其架构中嵌入了隐私原则和数据保护机制(设计保护隐私)。EUBIROD 的一个特定任务是调查参与中心之间实施欧盟数据保护指令(DPD)的可变性。
通过向所有参与的糖尿病登记处发放特定问卷来评估对隐私要求的遵守情况。项目包括相关问题,例如患者同意、数据保管人的问责制、沟通(透明度)和投诉程序(挑战合规性)、披露权、准确性、个人信息的访问和使用以及匿名化。识别特定的评分系统和统计软件允许对问卷回答进行全面的定性和定量分析,并通过专用 IT 平台(“隐私绩效评估”)进行独立评估。
来自不同国家的 18 个糖尿病登记处完成了调查。超过 50%的登记处在问责制、透明度、匿名化和挑战合规性方面获得了最高分。披露和处置、访问、同意、个人信息的使用和准确性的平均得分较低。在匿名化、同意、准确性和访问方面发现了很高的异质性。
EUBIROD 中实现的隐私绩效评估新方法可以提高每个数据源对隐私的尊重,减少隐私原则实施的整体可变性,并有利于在欧洲范围内进行健全和合法的高质量数据跨境交换。